US12608322B2UtilityA1

Techniques of encrypting BMC and bios firmware and data in flash memory

Priority: Filed: Sep 19, 2023Granted: Apr 21, 2026
G06F 2212/1052G06F 12/1408
37
PatentIndex Score
0
Cited by
26
References
14
Claims

Abstract

In an aspect of the disclosure, a method, a computer-readable medium, and an apparatus are provided. The apparatus is a BMC. The BMC receives data to be written to a storage. The BMC encrypts the data using a stream encrypt engine to generate encrypted data. The BMC writes the encrypted data to the storage. The BMC receives encrypted data read from the storage. The BMC decrypts the encrypted data using a stream decrypt engine to generate decrypted data. The BMC provides the decrypted data to a component of the BMC.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of operation of a baseboard management controller (BMC), the method comprising:
 routing data to be written from a first hardware component of the BMC or a host of the BMC to a storage through a hardware data encrypt/decrypt component positioned in-line between the first hardware component and the storage, wherein the hardware data encrypt/decrypt component is separate from and external to the first hardware component;   encrypting the data using a stream encrypt engine of the hardware data encrypt/decrypt component to generate encrypted data;   writing the encrypted data to the storage;   routing encrypted data read from the storage to the first hardware component through the hardware data encrypt/decrypt component; and   decrypting the encrypted data using a stream decrypt engine of the hardware data encrypt/decrypt component to generate decrypted data.   
     
     
         2 . The method of  claim 1 , further comprising:
 receiving a control command; and   providing the control command to the storage without encryption and decryption.   
     
     
         3 . The method of  claim 1 , wherein encrypting the data comprises encrypting the data using a unique key associated with the stream encrypt engine. 
     
     
         4 . The method of  claim 3 , wherein the unique key is derived from a unique identifier of the BMC. 
     
     
         5 . The method of  claim 1 , wherein a size of the encrypted data equals a size of the data received to be written to the storage. 
     
     
         6 . The method of  claim 1 , wherein the storage comprises a serial peripheral interface (SPI) flash memory. 
     
     
         7 . The method of  claim 1 , wherein the data are a part of firmware of the BMC or a part of firmware of a Basic Input/Output System (BIOS) of a host of the BMC. 
     
     
         8 . A baseboard management controller (BMC) comprising:
 a hardware data encrypt/decrypt component positioned in-line between a first hardware component and a storage, wherein the hardware data encrypt/decrypt component is separate from and external to the first hardware component, the hardware data encrypt/decrypt component comprising:
 a stream encrypt engine configured to encrypt data to be written to the storage; and 
 a stream decrypt engine configured to decrypt encrypted data read from the storage; 
   a memory; and   a processing unit coupled to the memory and configured to:
 route data to be written from the first hardware component to the storage through the hardware data encrypt/decrypt component including providing the data to the stream encrypt engine for encryption, wherein the stream encrypt engine provides the encrypted data to the storage; and 
 route encrypted data read from the storage to the first hardware component through the hardware data encrypt/decrypt component including providing the encrypted data to the stream decrypt engine for decryption. 
   
     
     
         9 . The BMC of  claim 8 , wherein the processing unit is further configured to:
 receive a control command; and   provide the control command to the storage without encryption and decryption.   
     
     
         10 . The BMC of  claim 8 , wherein the stream encrypt engine is configured to encrypt the data using a unique key associated with the stream encrypt engine. 
     
     
         11 . The BMC of  claim 10 , wherein the unique key is derived from a unique identifier of the BMC. 
     
     
         12 . The BMC of  claim 8 , wherein a size of the encrypted data equals a size of the received data to be written to the storage. 
     
     
         13 . The BMC of  claim 8 , wherein the storage comprises a serial peripheral interface (SPI) flash memory. 
     
     
         14 . The BMC of  claim 8 , wherein the data is a part of firmware of the BMC or a part of firmware of a Basic Input/Output System (BIOS) of a host of the BMC.

Join the waitlist — get patent alerts

Track US12608322B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.